NTP Kiss-o-Death Packet

Strike ID:
D15-8y001
CVSS:
7.5 CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
False Positive:
f
Variants:
2
Year:
2015

Description

This strike sends a Network Time Protocol(NTP) Kiss-o'-Death (KoD) Packet with the poll interval set higher than the defined maximum. Kiss-o'-Death packets are used by NTP servers to rate-limit ntp client requests that query too frequently. By sending a KoD packet with a larger poll value and a spoofed source IP address for any pre-configured NTP servers, a remote, unauthenticated attacker could disable NTP on a targeted system.

CVE

References

Bid